#145 · Local PDF inspection

PDF Embedded File Detector

Check PDF object structures for embedded-file specifications and attachment names without opening or extracting embedded content.

Choose a PDF

Processed in your browser
Ad space

How to use PDF Embedded File Detector

  1. Select one PDF. Password-protected or damaged files may not open.
  2. Run the local inspection and review each finding with its evidence.
  3. Download the JSON report for your records. Treat findings as review leads, not a malware verdict.

What this tool checks

Looks for EmbeddedFile streams, Filespec objects, embedded-file name trees, and attachment-related names without extracting or opening payloads.

The PDF stays in this browser tab. No detected link, script, attachment, or action is opened or executed.

Supported formats and limits

InputOne standard PDF file
OutputOn-screen findings and a JSON report
LimitsEncrypted, malformed, XFA, or heavily obfuscated PDFs may expose incomplete information.

Tips for better results

  • Keep the original untouched until your review is complete.
  • Confirm flagged URLs in a separate security workflow before visiting them.
  • Use a dedicated sanitizer when you must remove active content.

FAQ

Can PDF Embedded File Detector inspect a password-protected PDF?

Only when the browser PDF engine can open it without a password prompt. Encrypted content that cannot be decoded is reported as unsupported.

Does PDF Embedded File Detector upload my document?

No. The selected file is read locally in the browser, and the downloadable report is generated in the same tab.

Can a clean result prove that my PDF is safe?

No. Static browser checks can miss encrypted, malformed, or deliberately obfuscated content. Use the report as one part of a security review.

Will PDF Embedded File Detector change or sanitize the original PDF?

No. This viewer creates a report and never rewrites the selected source file.

Why might PDF Embedded File Detector show incomplete findings?

Complex XFA forms, encrypted object streams, nonstandard actions, and damaged cross-reference data may not be fully exposed by browser libraries.

Review guidance

InfoDocument fact; usually no immediate action.
ReviewCheck the finding in context.
HighDo not interact until independently verified.